Junior Cybersecurity & Physical Security Assessor (Oregon/Willing to Travel)

Eugene, OR
Advisory – IT Security Advisory /
Full-time /
Hybrid
BPM – where caring and community is in our company DNA; we are always striving to be our best selves; and we’re compelled to ask the questions that lead to innovation.
 
Working with BPM means using your experiences, broadening your skills, and reaching your full potential in work and life—while also making a positive difference for your clients, colleagues, and communities.  Our shared entrepreneurial spirit drives us to see and do things differently.  Our passion for people makes BPM a place where everyone feels welcome, valued, and part of something bigger. Because People Matter. 


Position Overview
This position works within a team of cybersecurity & physical security professionals to complete complex security assessments across a variety of industries. The primary focus of this position is to help a team of assessors complete offensive security engagements such as penetration tests and red team engagements. Duties within the team begin at an entry level, but a solid understanding of standard penetration testing principals and how to safely execute them is expected.
A primary responsibility of this position is to perform extensive social engineering assessments. Social engineering tests attempt to manipulate client employees under contract to evaluate their willingness to disclose sensitive information and permit unauthorized actions. Forms of social engineering can include email-based phishing, phone calls, SMS texts, and in person assessment.

Physical security audits are focus of the position to evaluate how well an organization protects its people, facilities, and physical assets against theft, sabotage, natural disasters, and other real-world threats. Existing knowledge of physical vulnerabilities is a benefit, but extensive hands-on training is provided.
Entry-level technical testing is a potential responsibility of the position and includes open-source intelligence gathering, phone system testing, external vulnerability exploitation.
Audit findings are documented in complex reports and then presented to the client. Successes candidates must be comfortable writing and documenting audit findings that are complex, and high-quality. 

Job Responsibilities:

    • Perform phone-based social engineering
    • Perform onsite social engineering testing, from target acquisition, to script preparation and approval, to execution and reporting
    • Perform physical security assessment of client facilities
    • Research and develop onsite attack tools, both physical and technical
    • Perform WiFi security assessments
    •  Document and report on all identified vulnerabilities
    • Present technical findings to non-technical stakeholders
    •  Complete all mission objectives including customer satisfaction

Qualifications:

    • Demonstrated experience in IT, computer science, IT auditing, electrical engineering, or a related field
    • Documented oral and written communication skills including complex technical document preparation
    • Experience with the Linux operating system
    • Basic computer networking fundamentals
    • Effectively document complex assessments in a timely fashion
    • Experience traveling within North America
    • Develop and maintain client relationships
    • Research and apply complex information security concepts for auditing, assessment, and testing procedures
    • Ability to work within a team environment to complete complex tasks

Experience:

    •  Linux: 1 year (Preferred)
    • Computer networking: 1 year (Preferred)
    •  Professional work: 5 years (Preferred)

Bonus Points:

    • Debate club, theater, or acting classes
    • Locksmith training
    • Electrical engineering background
    • Experience setting up a home-lab
    • Demonstrated interest in cybersecurity
    • Participation in CTF events
    • Relevant industry certifications or formal education (A+, Security+, Network+, minor in CS, etc.)

Other Requirements:

    • The position is often sedentary and requires sitting/standing for long periods of time.
    • This position requires regular overnight travel (30-50% in peak busy season).

What you get:

    • Total rewards package: from flexible work arrangements to personalized benefit structures and financial compensation options that give you choice and flexibility. 
    • Well-being resources: interactive wellness platform and incentives, an employee assistance program and mental health resources, and Colleague Resource Groups (CRGs) that provide safe spaces for colleagues to share, be heard, feel valued and deepen connections.
    • Balance & flexibility: 14 Firm Holidays including 2 floating, Flex PTO, paid family leave, winter break, summer hours, and remote work options, so you can balance challenging yourself with taking care of yourself. 
    • Professional development opportunities: A learning culture with CPA exam resources and bonuses, tuition reimbursement, a coach program, and live classes, workshops, and seminars through BPM University.

Who is successful at BPM:

    • Caring people who put others first 
    • Self-starters who embody the BPM entrepreneurial spirit 
    • Authentic individuals with a diverse point of view 
    • Lifelong learners with a drive to excel 
    • Resilient people who rise to the occasion 
$48,000 - $55,000 a year
*The salary range provided is intended for candidates in the San Francisco Bay Area who meet the minimum requirements of the position.  Candidates who do not reside in the San Francisco Bay Area, do not meet the minimum requirements, or exceed the requirements are encouraged to apply and a recruiter will provide you with a range specific to your location and qualifications.
Wondering if you should apply?

At BPM we are people who value people. We are progressive and purposeful. We are a firm with flexibility. Our shared entrepreneurial spirit drives us to see and do things differently. And our passion for people makes BPM a place where everyone feels welcome, valued, and part of something bigger.

***************

BPM provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

For positions based in San Francisco, consideration of qualified candidates with arrest and conviction records will be in a manner consistent with the San Francisco Fair Chance Ordinance.

Please note - this posting is for prospective candidates only. Unsolicited third-party resume submissions will be considered property of BPM and will not be acknowledged or returned.